CVE-2026-0243

Prisma SD-WAN: Denial of Service (DoS) Vulnerability Through IPv6 Crafted Packet

Severity
Medium 4.9
CVSS 4.0
Adjacent, local or physical access what this means
Exploited
Not listed
EPSS
0.002
6.1th percentile
Discovered by
Vendor
Vendor-published field
Published
May 13, 2026
Assigned by palo_alto

Description

A denial of service (DoS) vulnerability in Palo Alto Networks Prisma SD-WAN ION devices enables an unauthenticated attacker in a network adjacent to a Prisma SD-WAN ION device to cause a system disruption by sending a specially crafted IPv6 packet.

Weakness: CWE-606

Affected products

Vendor Product Category Matched by
Palo Alto Networks Prisma SD-WAN SASE / SSE / Secure Web cna-assigner
Vendor-reported products (1)
  • Palo Alto Networks · Prisma SD-WAN ION

Credit

Palo Alto Networks thanks our internal security research teams for discovering and reporting this issue.

Vendor remediation

Version Minor Version Suggested Solution Prisma SD-WAN ION 6.5 6.5.1 through 6.5.3 Upgrade to 6.5.3-b15 or later. Prisma SD-WAN ION 6.4 6.4.1 through 6.4.3 Upgrade to 6.4.3-b8 or later. Prisma SD-WAN ION 6.3 6.3.1 through 6.3.6 Upgrade to 6.3.6-b10 or later. Prisma SD-WAN ION 6.1 No action needed. Prisma SD-WAN ION 5.6 No action needed.

Something wrong here?